CVE-2025-68493: Apache Struts
High severity, CVSS 8.1. EPSS: 45.8% chance of exploitation in the next 30 days.
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Affected products
- Apache Struts: from 2.0.0, up to and including 2.3.37; from 2.5.0, up to and including 2.5.33; from 6.0.0, before 6.1.1 (fixed in 6.1.1)
Published 2026-01-11. Last modified 2026-07-15.